k8s-secure-baseline

Compliant GitOps platform on self-managed Kubernetes.

LayerTechnology
IaCOpenTofu + Terragrunt
Node provisioningAnsible + kubeadm
CNICilium 1.19
GitOpsArgoCD (app-of-apps)
Ingressingress-nginx (hostNetwork)
TLScert-manager + Let's Encrypt
DNSdeSEC (wildcard A record)